All skills
aws avatar

/aws-security

@21be518

Covers AWS security services and workflows — Security Hub V2 (OCSF) findings, connectors, aggregators, automation rules, and security posture summaries; Security Hub CSPM (V1/ASFF) controls and compliance standards; GuardDuty threat findings; Inspector vulnerability findings; Macie sensitive data findings; Detective investigation; and Security Lake configuration and data aggregation. Applicable when questions involve security posture, Exposure findings, CSPM failed controls, threat findings, vulnerability findings, sensitive data findings, automation rules, or cross-service security configuration across AWS environments. Procedures use standard AWS CLI syntax and work with or without the AWS MCP server.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/aws-security

This session only. Nothing lands on disk.

referencesinspector-findings.md

≈915 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Summarizing Inspector Findings

Overview

Produces structured summaries of Amazon Inspector findings — severity distribution, finding type breakdown, and affected resources. Does NOT perform remediation prioritization or patching recommendations.

Works from both standalone accounts and delegated administrator accounts.

Classify the Request

User intent Workflow
Summarize my Inspector findings A: Account Findings Summary
What vulnerabilities does Inspector see A: Account Findings Summary
Show vulnerability posture across org B: Organization Findings Overview
Which accounts have most critical vulns B: Organization Findings Overview

Workflow A: Account Findings Summary

  1. Get aggregated counts by severity:

    aws inspector2 list-finding-aggregations --aggregation-type ACCOUNT
  2. Get aggregated counts by finding type:

    aws inspector2 list-finding-aggregations --aggregation-type FINDING_TYPE
  3. Get aggregated counts by resource type:

    aws inspector2 list-finding-aggregations --aggregation-type AWS_EC2_INSTANCE
    aws inspector2 list-finding-aggregations --aggregation-type AWS_LAMBDA_FUNCTION
    aws inspector2 list-finding-aggregations --aggregation-type AWS_ECR_CONTAINER
  4. For ECR context, aggregate by repository:

    aws inspector2 list-finding-aggregations --aggregation-type REPOSITORY
  5. For EC2 context, aggregate by AMI:

    aws inspector2 list-finding-aggregations --aggregation-type AMI
  6. Present summary:

    Severity Count
    Critical N
    High N
    Medium N
    Low N
    Finding Type Count Highest Severity
    PACKAGE_VULNERABILITY N CRITICAL
    CODE_VULNERABILITY N HIGH
    NETWORK_REACHABILITY N MEDIUM
    Resource Type Count Critical+High
    AWS_EC2_INSTANCE N N
    AWS_ECR_CONTAINER_IMAGE N N
    AWS_LAMBDA_FUNCTION N N

    SHOULD include top 5 AMIs/repositories/functions by finding count when relevant.

Workflow B: Organization Findings Overview

  1. Aggregate by account:

    aws inspector2 list-finding-aggregations --aggregation-type ACCOUNT
  2. Present per-account summary:

    Account ID Critical High Medium Low Total
    111111111111 N N N N N

    MUST identify the top 5 accounts by critical+high findings count.

  3. Get overall finding type distribution:

    aws inspector2 list-finding-aggregations --aggregation-type FINDING_TYPE

Constraints

  • MUST use list-finding-aggregations for counts (not list-findings + manual counting)
  • MUST NOT perform remediation prioritization or patching recommendations
  • MUST NOT make suppression or exception recommendations
  • SHOULD present accounts sorted by critical+high count descending
  • MUST paginate aggregation results if response includes nextToken

Troubleshooting

Symptom Resolution
list-finding-aggregations returns empty No active findings — report zero findings
Only sees own account Not a delegated admin — note: single-account view only
ACCOUNT aggregation shows one entry Standalone account — use Workflow A

Output Sensitivity

Finding aggregations contain EC2 instance IDs, AMI IDs, ECR repository names, Lambda function ARNs, package names with CVE identifiers, and CVSS scores. Present the severity/type aggregation table first. Display full finding details only when the caller explicitly requests raw output.

Source: SKILL.md on GitHub

No alerts1mo3 checks · Risk SAFE
  • Gen Agent Trust Hub1mo

    This skill provides a structured framework for auditing AWS security services using read-only CLI commands. It covers configuration reviews and findings summarization for services like GuardDuty, Inspector, and Security Hub, emphasizing data sensitivity and least-privilege principles.

  • Socket1mo

    No alerts

  • Snyk1mo

    Risk: LOW · No issues

Signed by skilld at 21be518. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "version": "1"
}

README badge

README badge for aws/agent-toolkit-for-aws/aws-security